Expand description
Publishing from GitHub Actions without a secret (RFC-108 D5).
A job asks the runner for an OIDC token whose audience is the console’s
URL and sends it as Authorization: Bearer. Verifier::verify checks
the token’s signature against the issuer’s published keys, its issuer,
audience, and validity window, and that the repository’s owner is one the
console trusts. The caller then binds the report to the token’s
repository claim.
Structs§
- Trust
- A source of tokens the console accepts:
github:<owner>. The provider prefix is kept so GitHub Enterprise Server and GitLab can be added without changing how trusts are stored or shown. - Verified
Token - The claims of an accepted token the console uses.
- Verifier
- Verifies GitHub Actions tokens for one console.
Enums§
- Oidc
Error - Why a token was not accepted.
Constants§
- GITHUB_
ISSUER issof a GitHub Actions token.- GITHUB_
JWKS_ URL - Where GitHub publishes the keys that sign its tokens.